CVE-2026-83327
moderateUnauthenticated SOAP Flaw in Oracle E-Business Suite Framework Allows Full Takeover
CVE-2026-83327 is a critical vulnerability (CVSS 9.8) in the Personalization component of Oracle Applications Framework within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker who has network access to the target via SOAP, requiring no privileges or user interaction. A successful attack allows the attacker to compromise Oracle Applications Framework and take it over, with high impact on the confidentiality, integrity, and availability of the affected system. Any organization running E-Business Suite Release 12.2 in the affected version range is potentially exposed, particularly instances with SOAP endpoints reachable from untrusted networks. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of this writing.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83327 to all E-Business Suite 12.2.3-12.2.15 environments as a top priority given the unauthenticated, network-exploitable nature of the flaw. Until patched, restrict or block unauthenticated network access to SOAP endpoints on the EBS web tier using firewall/WAF rules, and allow-list only trusted integration sources. Review HTTP/SOAP access logs for anomalous unauthenticated requests targeting Applications Framework Personalization services, and treat any confirmed compromise as a full-takeover incident.
| Oracle E-Business Suite (Oracle Applications Framework, Personalization component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.